Description
A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may bypass Gatekeeper checks.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized execution of unsigned code
Action: Immediate Patch
AI Analysis

Impact

The flaw is a logic defect in macOS’s Gatekeeper system that can enable an application to bypass the built‑in code‑signing checks. This bypass allows unsigned or malicious software to run with the privileges of the installing user, potentially compromising confidentiality, integrity, and availability by providing the attacker with a local execution vector. The weakness is an instance of improper access control, as it permits execution that Gatekeeper is intended to prohibit.

Affected Systems

Apple macOS releases affected are macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, and macOS Tahoe 26.7. Earlier or later releases are considered unaffected unless Apple explicitly notes otherwise.

Risk and Exploitability

The CVSS score is not disclosed, and the EPSS score is unavailable, indicating no publicly available data on exploitation probability at this time. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploits. The likely attack vector is local: a user who installs an application that has circumvented Gatekeeper, requiring user interaction. If Gatekeeper is disabled or allows unsigned applications, the risk is elevated; otherwise the attacker must first trick or coerce the user to run a malicious package. Overall risk remains moderate to high for systems with Gatekeeper disabled or configured to allow non‑trusted installs, while enhanced controls can mitigate it.

Generated by OpenCVE AI on September 15, 2026 at 11:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the macOS update that includes the Gatekeeper bypass fix (macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6/26.7 or newer).
  • Ensure Gatekeeper is enabled in System Settings → Security & Privacy → General, selecting only App Store or signed developers as allowed sources.
  • If an OS update cannot be applied immediately, restrict installation of unsigned applications by configuring Gatekeeper to block unknown developers and educate users to avoid running software from unverified sources.

Generated by OpenCVE AI on September 15, 2026 at 11:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Gatekeeper Bypass Allowing Unsigned Application Execution
Weaknesses CWE-285

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may bypass Gatekeeper checks.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:49:03.117Z

Reserved: 2026-03-03T16:36:03.983Z

Link: CVE-2026-28899

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:05.167

Modified: 2026-09-14T21:17:05.167

Link: CVE-2026-28899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T11:15:18Z

Weaknesses